CryptoReal
CASE FILE — Sep 23, 2024

Shezmu Negotiates Return of $4.9M After Vault Exploit

Shezmu lost roughly $4.9 million from one of its vaults on September 20, in an incident that ultimately ended through direct negotiation with the attacker rather than a permanent loss of funds.

The root cause was a vault configured to accept collateral that could be minted by anyone. An opportunistic attacker used this flaw to borrow an unlimited amount of ShezUSD, siphoning millions out of the protocol.

Rather than simply absorbing the loss, Shezmu confronted the attacker directly: return the funds within 24 hours in exchange for a 10% bounty, or face legal action. The attacker pushed back, demanding 20% instead — and Shezmu agreed to those terms.

Credit for identifying and reporting the incident: Chaofan Shou, Shezmu.

Chaofan Shou, co-founder of blockchain analytics firm Fuzzland, was among the first to publicize the attack, stating that "ShezmuTech has been hacked / rugged. ~$4.9M worth of $ShezUSD stolen."

At the core of the incident was a vault that accepted attacker-mintable collateral, letting the attacker borrow an arbitrary amount of ShezUSD against it.

Notably, Shezmu had pushed a contract upgrade just 17 days before the exploit, on September 3rd (transaction 0x8db5356ec348a991adaadfd7f366d72eccafcb0113c7ac31f1dddde9c8c3f81e). It remains unclear whether that upgrade introduced the vulnerability outright or simply failed to close an existing gap.

On-chain analysis traced the exploit to the following addresses and transactions:

Attack Contract: 0xEd4B3d468DEd53a322A8B8280B6f35aAE8bC499C

Sums referenced in this case file

Shezmu attacker (contract creator): 0xA3a64255484aD65158AF0F9d96B5577F79901a1D

Attack contract creation transaction: 0x39328ea4377a8887d3f6ce91b2f4c6b19a851e2fc5163e2f83bbc2fc136d0c71

The attacker deployed a purpose-built contract to carry out the exploit rather than exploiting the flaw manually.

During the attack, Shou noted an important detail: due to low liquidity, the roughly $4.9 million in stolen ShezUSD could only actually be swapped for about $700,000 in other assets — meaning the attacker's realizable gain was far smaller than the headline figure.

Shezmu's team moved quickly once the attack was discovered, issuing a public statement warning users away from the dApp while they investigated, and then contacting the attacker directly with the 10% bounty offer in exchange for returning the funds.

The offer came with a clear ultimatum: cooperate and it would be treated as a whitehat rescue; refuse and face legal consequences. The attacker initially held out and countered with a 20% demand.

The resulting on-chain negotiation was notably civil given the sums involved, and ended in an agreement at the attacker's 20% terms. Shezmu subsequently confirmed the funds had been returned, minus the agreed bounty, in this transaction, and said a post-mortem would follow.

The low-liquidity constraint on the stolen ShezUSD — where $4.9 million in tokens could only be converted to roughly $700,000 — likely made the 20% bounty on the full stolen amount comparatively more attractive to the attacker than trying to liquidate the tokens directly.

Ultimately, the episode leaves open whether the resolution was driven by the threat of legal action, the size of the bounty, the attacker's own liquidity constraints, or some combination of the three.

The underlying issue, however, remains that Shezmu's September 3rd contract upgrade was not adequately reviewed before deployment, leaving the vault exposed. While the negotiated 20% bounty limited the damage, it does not address the review process gap that allowed the vulnerability to ship in the first place — a recurring pattern in DeFi where routine upgrades introduce new exploit paths.

Shezmu
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.